WhiteCanyon VP Nathan Jones walks me through a live demo of WipeDrive using a VMware ESXi 6.7 VM in TinkerTry's home lab!

Posted by Paul Braren on Jan 18 2020 (updated on Feb 13 2020) in
  • Efficiency
  • ESXi
  • Review
  • Security
  • Storage
  • White Canyon Software has been in the business of certified drive wipes for over 21 years! It's about time I had a look for myself, here's their WipeDrive 9 Product Page.

    Disclosure:
    This unpaid article and video demonstrates WipeDrive by WhiteCanyon. WhiteCanyon has run an occasional ad through BuySellAds on TinkerTry.com within the past 12 months, but their product is consistent with the themes of this site. I reached out to them to record the video. The article was created after using their product in my home lab. This article features income-earning affiliate links.

    Some hurried home lab enthusiasts who need to wipe a HDD or SSD may find themselves thinking about DBAN (Darik's Boot and Nuke), only to realize it hasn't been updated in many years, it doesn't do SSDs, and it provides no certificate. There are tools that I've talked about here at TinkerTry before such as Parted Magic that does offer SSD/NVMe secure erase. But when it comes to doing some actual consulting that should include a receipt that the work was done correctly, the quick-and-dirty approach isn't going to cut it. Let me explain.

    2020-01-18_22-50-32

    During my recent revisit to the federal sector last year, I spent considerable time in the DC area doing hands-on consulting again, much like I had done in the early 2000s. This experience got me thinking that it sure would be good to bone up on how a proper drive wipe is done these days, with all the right certification documentation to prove that it was done properly. I've had some experience with this at prior jobs including at IBM, where customers paid more to choose the drive retention option to never allow a drive out of the datacenter, or they'd just pay a consultant to do the drive wipes for them. What about if a consultant wants to do a drive wipe themselves?

    2020-01-18_22-46-36

    So I reached out to White Canyon and I got a rather quick response. The VP of Sales offered to go through the product with me, along with its positioning in the marketplace. We fired up a web meeting, I hit the record button, we introduced ourselves, and we got going with the demonstration. I quite enjoyed the whole experience, I hope you will too, when you watch the video below.

    WIPEDRIVEinESXi-by-Paul-Braren-at-TinkerTry
    ISO mounted in a VM, with an NVMe drive passed through. Unsupported but convenient.

    I had this crazy idea that a little twist might be fun, and that figuring out if I could also get their product working not just when booted from an ISO, but also from a running VMware ESXi host. How? How about about SATA drive pass through for motherboards that support it, or in my particular configuration, NVMe pass through for the NVMe SSD I had on hand. For those interested, I've documented how that's done here, and for this run, I chose these VM settings (way overkill) using just my ESXi 6.7 Update 3 home lab, a stock 8 core Supermicro SuperServer Bundle. Note that to get mouse support working in this Linux VM, you'll need to follow along, having learned the hard way with an incorrect VM setting used back when this mouse-less video was recorded.

    VMware ESXi 6.7 Update 3 Virtual Machine Settings:

    • CPU 2
    • Memory 4 GB
    • Guest OS Linux
    • Guest OS Version Ubuntu Linux (64-bit) (other Linux OS settings will work, but without mouse support)
    • CD/DVD drive 1
      / Datastore ISO File
      / wd-enterprise-dongle.iso

    While full access to the underlying hardware should be available when you pass through a drive using SATA passthrough, NVMe passthrough, or even RDM mappings, I'd recommend going with a fully supported native boot if you're actually doing consulting, not just preparing for it. Yes, normal people would use a fully supported configuration, imagine that!

    Activate-WipeDrive
    ISO mounted via iKVM, a supported method of booting WipeDrive.

    If your system has a CD/DVD reader, you can burn the WipeDrive ISO, then boot your system from that. But I took a more modern approach, especially since I don't have a CD/DVD reader. The process is something just like this,

    Supported bare-metal boot:

    • Download latest wd-enterprise-dongle.iso
    • Use Rufus to create a bootable USB flash drive out of it
    • Shutdown the system
    • Insert the drives to wipe, and remove all others if you can, I used a Samsung 960 M.2 SSD to demonstrate
    • Power up, then choose F11 (or similar) for the one-time boot device selection, picking the USB drive
    • Alternatively, use something like HPE iLO, Dell EMC iDRAC, or in Supermicro's case, iKVM, to remotely mount the ISO that you're booting from

    Hopefully this video below gives you enough of a feel for the product that you might consider giving it a go for yourself. They are very fast at turning around key requests, and of course they handle secure locations where a local key (rather than cloud activation) is required.

    Price

    B07KMRSFBV
    Available on Amazon.

    What about in a home lab? No problem, WipeDrive Home is available for $19.95:

    WipeDrive completely erases ALL hard drive or external storage information including your personal data, programs, viruses and malware. Using WipeDrive's military grade wiping technology your data will be impossible to recover even with the most sophisticated tools.
    Single use license. After initial purchase, additional uses ($10/each) can be purchased here.

    Compatibility

    Technical Details:

    • All computers with an x86 architecture
    • All versions of Microsoft® Windows® (Windows 8 and 10 with disabled boot security)
    • Intel-based Mac computers (starting with OS X v10.6 "Snow Leopard") that can boot from a CD
    • Linux machines that can boot from a CD

    Support

    You can get in touch via chat, phone, email, or webform.

    Features

    Features and Benefits - Hard Drive Eraser Features

    WipeDrive erases 100% of your data, operating system and programs. Erased data is impossible to recover, even with the most advanced tools.
    Eradicate Stubborn Viruses, Malware, and Other Infections
    Some infections just can't be eradicated using traditional methods. By using WipeDrive, you'll be able to start fresh with absolute certainty that any viruses, malware, or other infections are completely gone.
    ...
    Trusted by U.S. Government and Fortune 100 Companies
    WipeDrive is used, approved and used exclusively by the Department of Defense and the U.S. Air Force, and is a trusted provider for many Fortune 100 companies including GM and Humana. Now the exact same wiping technology is available to the public.
    ...

    Video

    WhiteCanyon's Nathan Jones demonstrates WipeDrive using a VMware ESXi 6.7 VM in TinkerTry's home lab

    Screenshots

    2020-01-18_22-15-05
    2020-01-18_22-16-17
    WipeDrive9-no-return
    2020-01-18_22-19-46
    2020-01-18_22-17-01
    2020-01-18_22-20-22

    Certification

    Complete list of certifications here:

    • Common Criteria EAL 2+
    • US DoD 5220.22-M
    • NIST 800-88 REV 1 Compliant
    • Meets the Common Criteria Evaluation and Validation Scheme
      HIPAA
    • FACTA standards
    • Sarbanes-Oxley
    • US Army AR380-19
    • US Air Force System Security Instruction 5020
    • US Navy Staff Office Publication P-5329-26
    • US National Computer Security Center TG-025
    • NATO NIAPC
    • GB HMG Infosec Standard #5 Baseline
    • GB HMG Infosec Standard #5 Enhanced
    • German VSITR
    • Australian Defense Signals Directorate ACSI-33(X0-PD)
    • Australian Defense Signals Directorate ACSI-33(X1-P-PD)
    • Canadian RCMP TSSIT OPS-II Standard Wipe
    • CIS GOST P50739-95
    • CSEC ITSG-06
    • Standard single pass overwrite

    Disclosure:
    This unpaid article and video demonstrates WipeDrive by WhiteCanyon. WhiteCanyon has run an occasional ad through BuySellAds on TinkerTry.com within the past 12 months, but their product is consistent with the themes of this site. I reached out to them to record the video. The article was created after using their product in my home lab. This article features income-earning affiliate links.


    Photos

    WipeDrive-box-front-by--TinkerTry
    Front of tiny box I received from Amazon order.
    WipeDrive-box-back-by--TinkerTry
    Back of tiny box I received from Amazon order.

    See also at TinkerTry

    how-to-configure-vmdirectpath-pass-through-of-nvme-using-vsphere-client

    parted-magic-secure-erase-m2-nvme-update

    See also

    2020-01-18_22-30-08
    • WipeDrive Enterprise Free Trial

      When you submit this form, our representatives will contact you to learn more about your company's needs. If your contact information is invalid, we will not be able to contact you about the trial.